Enhancing Information Security Awareness on Phishing Among It Students: A Pilot Test Case Study at Politeknik Tuanku Syed Sirajuddin
DOI:
https://doi.org/10.32890/jdsd2023.1.2Keywords:
Student awareness, Cybersecurity, Training awareness, Phishing AwarenessAbstract
Students engage with the core operations of university business processes, making them potential targets susceptible to significant cyberattack risks due to their limited experience and knowledge in information security. Consequently, IT students must gain awareness and competence in information security to mitigate potential threats and attacks, including those related to Information Technology (IT) security threats and the loss of valuable information and intellectual assets. This paper aims to assess the Phishing Awareness Program implemented at the Department of Information Technology and Communication (ITC) in Politeknik Tuanku Syed Sirajuddin (PTSS) and its students' awareness level. The significance of this study is focusing on students’ weaknesses and educating them about being cyber victims. Thirty students were involved in participating in this survey. They were given a set of questionnaires and performed pre-test and post-tests. After that, they were given three videos related to phishing and, later, three videos related to the consequences of phishing. Their awareness evaluation was performed after video training had been completed. Even though the score results of the post-test were increased and got positive feedback from respondents, several respondents still got the medium-level score. Suggestion for improvement was obtained to improve the current video content and its implementation. This work contributes to the information security awareness domain, where managers at higher learning institutions can replicate similar processes as proposed in this work in conducting similar training awareness with their students.
References
Burda, P., Chotza, T., Allodi, L., & Zannone, N. (2020). We are testing the effectiveness of tailored phishing techniques in industry and academia. Proceedings of the 15th International Conference on Availability, Reliability and Security. https://doi.org/10.1145/3407023.3409178
CJ, G., Pandit, S., Vaddepalli, S., Tupsamudre, H., Banahatti, V., & Lodha, S. (2018). PHISHY - A Serious Game to Train Enterprise Users on Phishing Awareness. Proceedings of the 2018 Annual Symposium on Computer-Human Interaction in Play. https://doi.org/10.1145/3270316.3273042
Desolda, G., Ferro, L. S., Marrella, A., Catarci, T., & Costabile, M. F. (2022). Human Factors in Phishing Attacks: A Systematic Literature Review. ACM Computing Surveys, 54(8), 1–35. https://doi.org/10.1145/3469886
Gandhi, A. (2017). Quantitative Assessment of Information Security Awareness on Informatics Students in a University. Proceedings of the 2017 International Conference on Information Technology - ICIT 2017. https://doi.org/10.1145/3176653.3176728
Higashino, M. (2019). A Design of an Anti-Phishing Training System Collaborated with Multiple Organizations. Proceedings of the 21st International Conference on Information Integration and Web-Based Applications & Services, iiWAS2019. https://doi.org/10.1145/3366030.3366086
Moul, K. A. (2019). Avoid Phishing Traps. 2019 ACM SIGUCCS Annual Conference on - SIGUCCS ’19. https://doi.org/10.1145/3347709.3347774
Qasaimeh, M., Al-Manaseer, H., Al-Manaseer, H., & Alghanim, F. (2021). Status Update on Phishing Emails Awareness: Jordanian Case. The 7th International Conference on Engineering & MIS 2021. https://doi.org/10.1145/3492547.3492565
Sharevski, F., Devine, A., Pieroni, E., & Jachim, P. (2022). Phishing with Malicious QR Codes. 2022 European Symposium on Usable Security, EuroUSEC ’22. https://doi.org/10.1145/3549015.3554172
Sykosch, A., Doll, C., Wübbeling, M., & Meier, M. (2020). You are generalising the phishing principle. Proceedings of the 15th International Conference on Availability, Reliability and Security. https://doi.org/10.1145/3407023.3409205








